Library
|
Your profile |
Theoretical and Applied Economics
Reference:
Gavrishev, A.A. (2025). Information security labor market for healthcare institutions. Theoretical and Applied Economics, 1, 76–88. . https://doi.org/10.25136/2409-8647.2025.1.71839
Information security labor market for healthcare institutions
DOI: 10.25136/2409-8647.2025.1.71839EDN: NRNMTEReceived: 29-09-2024Published: 03-05-2025Abstract: This article analyzes the Russian labor market in the information security segment for healthcare institutions. It's noted that the active digitalization of healthcare institutions, the increased number of cyber attacks on its and the active change in legislation on information security determine the interest in research of this segment of the Russian labor market. It's shown that many publications provide data on the entire labor market in the information security segment, indicating the distribution of vacancies by industry, the distribution of vacancies by groups, requirements for candidates, salary levels, etc. At the same time, insufficient attention has been paid to the labor market in the information security segment for healthcare institutions. Based on this, research in this area requires further study. The research was mainly based on recent data from the HeadHunter and SuperJob portals. Using the example of Moscow and St. Petersburg, the most frequently found positions in vacancies were analyzed; requirements for the level of education; the structure of vacancies in terms of salary, work experience, types of employment and work schedules, as well as required labor functions. Based on the results obtained and data from known sources, conclusions are formulated. It's shown that for information security specialists working in healthcare institutions or just getting a job, not only requirements are imposed on the level of education and work experience, but also a fairly wide list of requirements for labor functions in information security. Therefore, the work of such specialists is quite complex and requires deep and versatile knowledge from various fields. This determines the difficulties in selecting a competent information security specialist for healthcare institutions. A number of general recommendations are proposed to improve the situation on the Russian labor market in the information security segment for healthcare institutions. Keywords: requirements, analysis, economics, management, labor market, vacancies, legislation, information security, employees, healthcareThis article is automatically translated. You can find original text of the article here. Introduction Currently, information security (IS) is one of the most important areas of activity of any Russian organization due to the increasing penetration of digital technologies into everyday life. In accordance with the Information Security Doctrine of the Russian Federation, approved by Decree of the President of the Russian Federation dated 05.12.2016 No. 646, information security refers to the implementation of interrelated legal, organizational, technical, personnel and other measures to predict, detect, contain, prevent, repel information threats and eliminate the consequences of their manifestation. The training of competitive information security specialists by educational institutions undoubtedly requires taking into account the needs of the labor market. In order to bring educational activities closer to practice in the field under consideration, there are numerous professional standards on information security, for example, the professional standard "Information Security Specialist in Automated Systems" (approved by Order of the Ministry of Labor of the Russian Federation No. 525n dated 09/14/2022), etc., which establish requirements for the qualifications and competencies of employees. Despite the fact that in recent years the government has doubled the number of budget places in educational institutions in the field of information security, however, there is still an acute shortage of information security specialists in the Russian labor market. For example, according to the Ministry of Labor and Social Protection of the Russian Federation, the annual shortage of personnel in the field of information security is 18,000 people. And according to the assessment of the Deputy Minister of the Ministry of Finance of Russia, A. Shoitov, 80% of companies and organizations covered by Presidential Decree No. 250 are experiencing an acute shortage of information security specialists [1]. Based on the above, research in the field of the labor market of information security specialists is relevant and requires further study. In this paper, the authors want to address one of the actively developing segments of the Russian labor market for information security specialists associated with healthcare institutions. The active digitalization of medical institutions, and the increased number of cyber attacks on such institutions at times, determine the interest in the research of the labor market segment [2-7] associated with such institutions. In particular, according to the statistics given in [6], Russian healthcare institutions in the first six months of 2024 were 32% more likely to become victims of hacker attacks with critical consequences than a year earlier. These include data leaks, the destruction of IT infrastructure, and the suspension of the institutions themselves. At the same time, experts assert [2-7] that cyber attacks on such organizations will become even more dangerous in the future due to the further digitalization of the healthcare industry and integration with government systems. In addition, in recent years, there have been active changes in the legislation on information security. So, since 2018, in accordance with the Federal Law "On the Security of Critical Information Infrastructure of the Russian Federation" dated July 26, 2017 No. 187-FZ, the healthcare sector has been classified as a critical information infrastructure (CII), and the requirements of relevant legislation began to apply to it. In these conditions, the issue of compliance of information security systems of healthcare institutions with the requirements established by the relevant legislation in the field of information security to ensure the security of personal data (PD), state information systems (GIS), CII, etc. (Federal Law "On Personal Data" dated 27.07.2006 No. 152-FZ, Federal Law "On the Security of Critical Information Infrastructure of the Russian Federation of the Russian Federation" dated July 26, 2017 No. 187-FZ, Decree of the President of the Russian Federation dated 05/01/2022 No. 250 "On Additional measures to ensure the Information Security of the Russian Federation", Decree of the Government of the Russian Federation dated 07/06/2015 No. 676 "On the requirements for the procedure for the creation, development, commissioning, operation and decommissioning of State information systems and further Storage information contained in their databases", etc.). Based on this, research is needed to assess the current state and trends of the Russian labor market in this area. The purpose of the study The purpose of this article is to analyze the Russian labor market in the information security segment for healthcare institutions. Materials and methods To achieve the purpose of the study, an analysis, description and synthesis of materials on this topic were carried out, which were based on data from various sources, in particular, the Consultant Plus help system, the RSCI, the HeadHunter and SuperJob portals, the Yandex search engine, etc. The general methodological basis is a systematic approach. Domain analysis We will analyze the subject area related to the research of the Russian labor market in the information security segment for healthcare institutions. The source [8] indicates that in 2022, an information security department appeared in 30% of Russian companies. However, finding the right specialists is problematic, as stated by more than half of Russian companies. It is noted that the current situation forces employers to reduce the requirements for future employees in information security departments. If in 2021, more than half of the vacancies were open strictly for specialists with experience from 1 to 3 years, then in 2022 there were less than half of them. The vacancy rates for experienced professionals (over 6 years old) and youth without experience remain the same, reflecting companies' willingness to train employees. It is noted that companies have begun to more clearly describe the requirements for the necessary labor skills, including those related to technical means of information protection, cryptographic information protection, etc. The median salary of information security specialists in the country has increased to 63,100 rubles against 59,500 rubles in 2021. Trokhimets K.'s work shows [9] that in 2023 alone, the number of vacancies for information security specialists in the Russian market increased by a third compared to 2022. It is noted that the search for the right information security specialists is problematic. A significant difference from the situation in late 2022 and early 2023 is the growing demand for information security specialists of various profiles, including employees without experience. The number of vacancies for the most experienced (6 years and above in the field) increased by 67%, for those who work from 3 to 6 years — by 43%, with 1-3 years of experience — by 30%, without experience — 41%. The average salary in information security in 2023 was about 70,000 rubles. The source [10] states that surveys show that every third company in Russia will need information security specialists. At the same time, more than half of all organizations would like to hire experienced specialists and heads of information security departments. However, finding the right specialists is problematic, as stated by a large number of companies. In the work of the team of authors, Evseev K., Isaev M., Murzina A., and others indicated [11] that in recent years, different industries have shown different demand for information security specialists. So they are most needed in the ICT sector, in the financial sector and in industry. The share of healthcare is estimated at about 3%. If we talk about professional skills, then almost a third of vacancies mention knowledge at the administrator level and practical experience in ensuring the security of various information systems using technical means of information protection and cryptographic means of information protection. The median salary of information security specialists is estimated at 80,000 rubles. The source [12] provides a study of the information security labor market in Russia, which determines the approximate number of people employed in the information security industry, the distribution of vacancies by industry, the distribution of vacancies by groups, their median salary, etc. In addition, an approximate forecast of the labor market for information security until 2027 is shown. The conducted research has revealed that more than half of the vacancies currently fall on specialists with up to 3 years of experience. The median salaries for Moscow, St. Petersburg and other regions of Russia are indicated. In particular, in Moscow, the salary of information security specialists is 86,000 for government organizations and 125,000 for commercial organizations, in St. Petersburg 58,000 and 92,000, respectively, in other regions of Russia – 40,000 and 65,000. It was noted that in the regional context, Moscow retains a high share in attracting information security specialists - 46% of vacancies in the second quarter of 2023 were in the capital. As can be seen from the works of various authors (Trokhimets K.; Evseev K., Isaev M., Murzina A., etc.) and other sources, they mainly provide data on the entire labor market of the Russian Federation in the information security segment, indicating the requirements for candidates, salary levels, etc. At the same time, insufficient attention has been paid to the labor market of the Russian Federation in the information security segment for healthcare institutions. Based on this, it is necessary to continue further research on this topic. Results We will conduct a study of the labor market of the Russian Federation in the information security segment for healthcare institutions, based on general recommendations from the works. [9, 11, 13, 14]. In order to determine the current situation on the Russian labor market in the area under study, the author of this work conducted an analysis of employer offers (in vacancies) from November 2023 to March 2024 based on data from the HeadHunter and SuperJob portals, as well as those visible by the Yandex search engine. As an example, the labor markets of Moscow and St. Petersburg were chosen as one of the largest and most developed in the Russian Federation. The data was uploaded on request for all information security-related professions, for which potential employers may be healthcare institutions. As a result of the analysis of approximately 1,000 vacancies in the field of information security, approximately 35 vacancies were selected on the subject under study. Among the positions considered, the following are the most common (Fig. 1). Figure 1. The most common positions in vacancies (compiled by the author) As can be seen from the data presented, the positions of "Information Security Specialist" and "Information Security Specialist" are most often found in vacancies (in 77% of cases). Despite the different names of these positions, in accordance with professional standards on information security, they belong to a group of specialists with higher education in the field of information security with basic requirements for the level of education and work experience. In other cases, the position of "Leading Information Security Specialist" was found. In accordance with professional standards on information security, she belongs to a group of specialists with higher education in the field of information security with increased requirements for the level of education and work experience. From the data obtained, it is possible to draw a preliminary conclusion that healthcare institutions, as employers, currently in most cases require employees with higher education in the field of information security with basic requirements for the level of education and work experience. Let's analyze employers' educational requirements. Since 100% of the analyzed vacancies indicated the requirement for higher education in the field of information security, we will analyze the vacancies for the requirements for the level of higher education (Fig. 2). Figure 2. Requirements for the level of higher education described in vacancies in the field under study: a) bachelor's degree, b) specialty / master's degree, c) higher education in the field of information security without specifying its level, d) higher education in the field of information security, or other higher education (usually technical) with the requirement of professional retraining in information security areas (compiled by the author)
According to the results of the analysis, it was found that 35% of vacancies indicated bachelor's degree in information security, 23% — specialist/master's degree, 22% — higher education in the field of information security without specifying its level, and 20% — higher education in the field of information security without specifying its level, or other higher education (usually technical) with the requirement of professional retraining in the field of information security. Thus, it should be concluded that healthcare institutions, as employers, require that information security specialists have specialized education. The results obtained are fully consistent with the requirements of the legislation on information security and professional standards on information security. To determine the degree of attractiveness of the profession in question in the Russian labor market, an analysis of the proposed salary was also carried out. An analysis of the proposed salary for the entire sample of vacancies shows (Fig. 3) that the minimum wage is about 60 thousand rubles, and the maximum is 140 thousand rubles. At the same time, the average salary for all vacancies is approximately 88 thousand rubles. Figure 3. The proposed salary for the entire sample of vacancies in the field under study (compiled by the author) An important prerequisite for hiring information security specialists is also their work experience (Fig. 4). Figure 4. Requirements for work experience in the field under study: a) no work experience; b) work experience from 1 to 3 years; c) work experience of 3-6 years (compiled by the author)
Most of the vacancies (68%) require work experience from 1 to 3 years. Nevertheless, there are a number of vacancies that do not require mandatory work experience (9%), which is important for university graduates. From 3 to 6 years of work experience is required in 23% of vacancies. In general, more work experience is required for higher positions. At the same time, 77% of all vacancies are for vacancies with a requirement of up to 3 years of work experience. These vacancies mainly fall on the positions of "Information Security Specialist" and "Information Security Specialist", which are positions with basic requirements for the level of education and work experience. The remaining 23% of all vacancies are mainly for vacancies with a requirement of 3 to 6 years of work experience. These vacancies fall on the position of "Leading Information Security Specialist", which is a position with high requirements for the level of education and work experience. Taking into account current trends in changing the nature of work, it is also advisable to consider the existing situation with the distribution of vacancies by type of employment and work schedule. The results of the analysis are shown in Fig. 5. Figure 5. Percentage distribution of vacancies by type of employment (a) and schedule of work in the organization (b) in the field under study (compiled by the author)
As shown in the graph (Fig. 5), traditional forms of employment of information security specialists for healthcare institutions, i.e. full-time employment (96% of vacancies) and full-time work schedule in the organization (90% of vacancies), still prevail. These results completely coincide with the current trends in the labor market, both in Russia and in the world. In particular, the remote work format, which has become entrenched during the pandemic years, is causing more and more objections from employers. They are beginning to get tired of employees' too vague work schedules in a hybrid mode, introduce stricter controls and set office visit schedules [15]. In addition, the high responsibility and complexity of the work carried out on information security require the presence of full-time employees in healthcare institutions. Based on this, these results generally coincide with the current situation on the labor market. However, 4% of vacancies offer part-time employment, and 10% of vacancies offer remote work. In addition, the requirements for the work functions described in the vacancies were clarified during the research. Taking into account the labor functions described in the vacancies, occupational safety standards, requirements of the legislation on information security and sources [3-12],[16-19], a simplified scheme was formed (Fig. 6), taking into account the set of generalized labor functions that information security specialists need to perform in healthcare institutions. Figure 6. A set of generalized labor functions that information security specialists need to perform in healthcare institutions (compiled by the author)
As can be seen from the data presented, information security specialists working in healthcare institutions or just getting a job are subject not only to requirements in terms of education and work experience, but also to a fairly wide range of requirements for information security work functions. Therefore, the work of such specialists is quite complex and requires deep and versatile knowledge from various fields. Discussion of the results obtained Based on the results obtained and data from various sources, it is possible to draw the following conclusions: 1) currently, due to the increased number of cyber attacks and the ongoing changes in legislation in the field of information security, there is an increasing need for information security specialists for healthcare institutions; 2) there are quite serious requirements for information security specialists for healthcare institutions in terms of their level of education, work experience, and work functions that must be performed in such institutions; 3) the task of selecting a competent information security specialist for healthcare institutions is quite a difficult task, since the requirements for such specialists, due to their work functions, are quite high. In addition, the existing shortage of personnel in the labor market also complicates this task. Based on the results obtained and data from sources [1-18], it is possible to propose a number of general recommendations that can potentially improve the situation on the Russian labor market in the information security segment for healthcare institutions: 1) it is advisable to expand the practice of targeted training of information security specialists for healthcare institutions with their subsequent employment; 2) it is advisable to expand the practice of training information security specialists for the needs of healthcare institutions through professional retraining in information security programs for their existing employees; 3) it is advisable to more actively introduce artificial intelligence systems and automation tools into the work of information security specialists in healthcare institutions to perform tasks that require a lot of time and resources; 4) It is possible to outsource certain types of information security work in healthcare institutions in compliance with legal requirements. Although, of course, the list of recommendations is not limited to the presented, however, the implementation of these measures, according to the author, will allow in the future to improve the situation on the labor market of the Russian Federation in the information security segment for healthcare institutions. Conclusion Thus, this article analyzes the labor market of the Russian Federation in the information security segment for healthcare institutions. It is shown that the literature currently pays insufficient attention to the labor market of the Russian Federation in the information security segment for healthcare institutions. As a result of the conducted research, which is based on data from the HeadHunter and SuperJob portals, as well as those visible by the Yandex search engine, using the example of Moscow and St. Petersburg, the following results were obtained: the most frequently found positions in vacancies were identified; an analysis of vacancies for educational level requirements was carried out; an analysis of the structure of vacancies by size indicators was carried out remuneration, work experience, types of employment and work schedules; a simplified scheme has been formed that takes into account the set of generalized labor functions that information security specialists need to perform in healthcare institutions. Based on the results of the study, the conclusions and recommendations are summarized. References
1. The bug bounty mechanism and the reward attack. How to solve the problem of shortage of cybersecurity specialists. Retrieved from https://rg.ru/2023/03/12/mehanizm-bagbaunti-i-ataka-za-voznagrazhdenie-kak-reshit-problemu-deficita-specialistov-po-kiberbezopasnosti.html
2. In a sore spot: the number of hacker attacks in medicine has increased by 91%. Retrieved from https://iz.ru/1157653/roman-kildiushkin/po-bolnogo-mestu-kolichestvo-khakerskikh-atak-v-meditcine-vyroslo-na-91 3. Hamidovic H., & Kabil J. (2011). An Introduction to Information Security Management in Health Care Organizations. ISACA Journal, 5, 1-5. 4. Nifakos, S., Chandramouli, K. Nikolaou, C.K. et al. (2021). Influence of Human Factors on Cyber Security within Healthcare Organizations: A Systematic Review, Sensors, 21, 1-25. doi:10.3390/s21155119 5. Gavrishev, A.A. (2024). Research of certain issues of personnel management on information security in healthcare institutions. Scientific Journal of ITMO Research Institute. The series "Economics and Environmental Management", 1, 31-41. doi:10.17586/2310-1172-2024-17-1-31-41 6. Medicine has caught the virus. Retrieved from https://www.kommersant.ru/doc/6852545 ?from=top_main_3 7. Hannah, T. Neprash, Claire C. McGlave, Katie Rydberg, & Carrie Henning-Smith. (2024). What happens to rural hospitals during a ransomware attack? Evidence from Medicare data. The Journal of Rural Health, 4, 728-737. doi:10.1111/jrh.12834 8. Salary is higher than expected. Retrieved from https://pro.rbc.ru/demo/636e1d979a7947f96327346f 9. Trokhimets, K. The labor market in the second quarter of 2023. Demand is growing, but information technology specialists are still in short supply. (2023). BIS Journal, 3. Retrieved from https://ib-bank.ru/bisjournal/post/2112 10. The IB does not know: the business lacks cybersecurity specialists. Retrieved from https://iz.ru/1518510/sergei-gurianov/ib-ne-vedaiut-biznesu-ne-khvataet-spetcialistov-po-kiberbezopasnosti 11. Evseev, K., Isaev, M., Murzina, A. et al. (2023). Data without danger. Innopolis: Innopolis University Publ. Retrieved from https://innopolis.university/filespublic/dannye_bez_opasnosti.pdf 12. The labor market in information security in Russia in 2024-2027: forecasts, problems and prospects. Retrieved from https://www.ptsecurity.com/ru-ru/research/analytics/preview/rynok-truda-v-informaczionnoj-bezopasnosti-v-rossii-v-2024-2027-gg-prognozy-problemy-i-perspektivy/?utm_source=pt&utm_medium=article&utm_campaign=issledovanie-czsr-severo-zapad-i-pt&utm_content=news#id1 13. Umnov, V.A. (2024). Analysis of labor market needs in personnel management specialists. Leadership and management, 1, 149-164. doi:10.18334/lim.11.1.120503 14. Sibirskaya, E.V., & Oveshnikova, L.V. (2023). The use of big data analytics technologies in the study of the dynamics and structure of the labor market in the field of professional activity. Economics and entrepreneurship, 2, 1002-1006. doi:10.34925/EIP.2023.151.2.196 15. Employers are bringing employees to the office en masse from a remote location. Retrieved from https://rg.ru/2024/02/25/udalennye-ili-nedalekie.html 16. Rodionycheva, E.D., & Golubev, A.S. (2021). Evaluation of the cost of purchasing a software and hardware complex to ensure information security of information systems in the field of healthcare. News higher educational institutions. Series: Economics, Finance and Production Management, 3, 124-129. DOI 10.6060/ivecofin.2021493.558 17. Nyamtsu, A.M., Zabokritskiy, O.V., & Yusupova, E.Yu. (2013). Problems of personal data protection in the field of healthcare. Medical science and education of the Urals, 3, 136-138. 18. Gulov, V.P., Kosolapov, V.P., Sych, G.V., & Khvostov, V.A. (2020). Organization of information protection in healthcare: monograph. Voronezh: Wholesaler of the Chernozem region Publ. 19. Azhmukhamedov, I.M. (2014). Management of sociotechnical systems (on the example of integrated information security systems): monograph. Rostov n/A: Publishing house of the YUNTS RAS.
First Peer Review
Peer reviewers' evaluations remain confidential and are not disclosed to the public. Only external reviews, authorized for publication by the article's author(s), are made public. Typically, these final reviews are conducted after the manuscript's revision. Adhering to our double-blind review policy, the reviewer's identity is kept confidential.
Second Peer Review
Peer reviewers' evaluations remain confidential and are not disclosed to the public. Only external reviews, authorized for publication by the article's author(s), are made public. Typically, these final reviews are conducted after the manuscript's revision. Adhering to our double-blind review policy, the reviewer's identity is kept confidential.
|